diff --git a/SPEC.md b/SPEC.md index 6908338..492507d 100644 --- a/SPEC.md +++ b/SPEC.md @@ -1303,7 +1303,10 @@ networks: - Core Rule Set false positives against real apps (a search for code, and any body once `WAF_BODY_LIMIT` is set): a match refuses only that request and bans no one by itself; the request log names the rule, and exclusions by rule id - and path fix it. + and path fix it. Further gitea requests the Core Rule Set may refuse at the + defaults, found by reading gitea's source rather than a running gitea, are + collected in https://git.eeqj.de/sneak/smallwebwaf/issues/30 and checked when + milestone 1 runs in front of a real gitea. - Attacks carried in request bodies: not refused by default, since on a code forge bodies are full of code the Core Rule Set takes for attacks. Most of what shows in URLs and headers is still refused, the client that sends an